Legal
Privacy Policy
Last updated 1 August 2026
What we collect, why we collect it, who else sees it, and how to get it back or get rid of it.
Template — not legal advice. This document was drafted to describe how ParcelAI actually works, but it has not been reviewed by a solicitor. Have counsel check it against your jurisdiction, your insurer and your data processors before you rely on it commercially.
1. Who we are
ParcelAI is the data controller for your account information, and a data processor for the supplier emails you forward to us — that content belongs to you, and we act on your instructions in handling it.
2. What we collect
Account data. Your email address, an encrypted password hash (or a Google account identifier if you sign in that way), your company name, and the record that you accepted these terms with a timestamp.
Forwarded email content. The subject and body of messages you forward, plus the values extracted from them: product name, SKU, quantity, availability, lead time and a confidence score.
Store credentials. API keys for the store you connect. These are encrypted at rest in Supabase Vault, and are never returned to a browser — not even yours.
Operational records. Activity log entries, sign-in times, and the approximate location and device of active sessions so you can spot access you do not recognise.
We do not connect to your mailbox. We only ever see what you forward.
3. Why we are allowed to hold it
- Performance of a contract — we cannot run the service without processing what you forward.
- Legitimate interests — keeping the service secure, preventing abuse, and debugging failures.
- Consent — for optional product email, which you can withdraw at any time.
- Legal obligation — retaining billing records for the period tax law requires.
4. Automated processing
Extraction is performed by large language models. This is automated processing, but it does not produce legal or similarly significant effects about a person: it reads product availability out of business correspondence.
Content is sent to our model provider for inference only. It is not used to train their models, and it is not retained by them beyond the processing window their terms specify.
5. Who else processes your data
- Supabase — database, authentication and file storage, hosted in the EU.
- Our model provider — inference over forwarded email content.
- Our payment provider — subscription billing. We never see or store your card details.
- Our email infrastructure provider — receiving forwarded mail and sending transactional email.
Each is bound by a data processing agreement. We do not sell personal data, and we do not share it for advertising.
6. How long we keep it
Stock updates and their source extracts are kept while your account is open, so the audit trail stays meaningful. Activity log entries are kept for 12 months.
Deleting your data from Settings removes your activity log, stock updates, supplier rules, vault secrets and workspace in a single transaction — if any part fails, none of it is deleted, so you never end up half-erased. Backups age out within 30 days.
7. Your rights
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to processing based on legitimate interests. You can also complain to your data protection regulator.
Most of this is self-service: export and deletion live in your dashboard settings. For anything else, contact us and we will respond within 30 days.
8. Security
Every table is protected by row-level security in Postgres, so tenant isolation is enforced by the database rather than by application code alone. Credentials are encrypted at rest, sessions use httpOnly cookies, and two-factor authentication is available on every account. More detail on the security page.
9. Cookies
We set a session cookie so you stay signed in, and nothing else. There is no advertising or cross-site tracking on this site, which is why you are not being asked to dismiss a consent banner.
10. Changes and contact
Material changes are notified by email or in the dashboard before they take effect. Questions, requests or complaints: contact us.